Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wf93-45jw-7689

Опубликовано: 01 июн. 2026
Источник: github
Github: Прошло ревью
CVSS4: 4.1
CVSS3: 8

Описание

pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

Ссылки

Пакеты

Наименование

pip

pip
Затронутые версииВерсия исправления

< 26.1.2

26.1.2

EPSS

Процентиль: 24%
0.0032
Низкий

4.1 Medium

CVSS4

8 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 месяцев назад

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

CVSS3: 8
redhat
2 месяца назад

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

CVSS3: 5.5
nvd
около 2 месяцев назад

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

msrc
около 2 месяцев назад

pip can extract console_scripts and gui_scripts outside installation directory

CVSS3: 5.5
debian
около 2 месяцев назад

pip would treat console_scripts and gui_scripts as paths instead of fi ...

EPSS

Процентиль: 24%
0.0032
Низкий

4.1 Medium

CVSS4

8 High

CVSS3

Дефекты

CWE-22